Several vulnerabilities have been discovered in the chromium web browser.
Category Archives: Debian
Debian Security Advisories
DSA-3527 inspircd – security update
It was discovered that inspircd, an IRC daemon, incorrectly handled
PTR lookups of connecting users. This flaw allowed a remote attacker
to crash the application by setting up malformed DNS records, thus
causing a denial-of-service,
DSA-3528 pidgin-otr – security update
Stefan Sperling discovered that pidgin-otr, a Pidgin plugin
implementing Off-The-Record messaging, contained a use-after-free
bug. This could be used by a malicious remote user to intentionally
crash the application, thus causing a denial-of-service.
DSA-3529 redmine – security update
Multiple vulnerabilities have been found in Redmine, a project management
web application, which may result in information disclosure.
DSA-3526 libmatroska – security update
It was discovered that libmatroska, an extensible open standard
audio/video container format, incorrectly processed EBML lacing. By
providing maliciously crafted input, an attacker could use this flaw
to force some leakage of information located in the process heap
memory.
DSA-3525 pixman – security update
Vincent LE GARREC discovered an integer overflow in pixman, a
pixel-manipulation library for X and cairo. A remote attacker can
exploit this flaw to cause an application using the pixman library to
crash, or potentially, to execute arbitrary code with the privileges of
the user running the application.
DSA-3524 activemq – security update
It was discovered that the ActiveMQ Java message broker performs unsafe
deserialisation. For additional information, please refer to the
upstream advisory at
http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt.
DSA-3523 iceweasel – security update
This update disables the Graphite font shaping library in Iceweasel,
Debian’s version of the Mozilla Firefox web browser.
DSA-3522 squid3 – security update
Alex Rousskov from The Measurement Factory discovered that Squid3, a
fully featured web proxy cache, does not properly handle errors for
certain malformed HTTP responses. A remote HTTP server can exploit this
flaw to cause a denial of service (assertion failure and daemon exit).
DSA-3521 git – security update
Lael Cellier discovered two buffer overflow vulnerabilities in git, a
fast, scalable, distributed revision control system, which could be
exploited for remote execution of arbitrary code.